Data Processing
Last updated: 1 January 2026
This page summarises how BLU Software (Pty) Ltd, a company registered in South Africa (“BLU”), processes data on behalf of its Clients when operating a Client's loyalty and engagement platform. Clients requiring a formal Data Processing Agreement (DPA) for compliance purposes should contact hello@goblu.tech.
1. Roles
In relation to end-customer data collected through a Client's platform, the Client acts as the data controller and BLU acts as the data processor, processing data only on the Client's documented instructions, except where BLU is required by law to do otherwise.
2. Platform Isolation
Each Client is provisioned an independent platform and database. Client data is never pooled, merged or made accessible across Clients. Access to a Client's platform is restricted to that Client's authorised users and to BLU personnel who require access to provide support, each under a duty of confidentiality.
3. What We Process
- End-customer profile data submitted to a Client's loyalty platform.
- Loyalty activity: visits, points earned and redeemed, and reward history.
- Communications sent via the platform on the Client's behalf.
4. Sub-processors
BLU currently engages the following sub-processor to help operate client platforms:
- Supabase: database hosting and authentication for the control platform and each Client's isolated project.
[TODO: list any additional sub-processors currently in use — e.g. application hosting, payment processing, or email/SMS delivery — or confirm Supabase is the only one]
All sub-processors are bound by contractual confidentiality and data protection obligations consistent with this page. We will notify Clients of any change in sub-processor and give them a reasonable opportunity to object before the change takes effect.
5. Security Measures
BLU applies encryption in transit, access controls scoped per Client, authenticated administrative access, and routine security review of the platforms it manages.
6. Security Incidents
If BLU becomes aware of a security incident affecting a Client's data, we will notify the affected Client without undue delay, provide the information reasonably available to us about the incident, and take reasonable steps to contain and remediate it.
7. Assisting with Data Subject Requests
Where an end customer contacts BLU directly to exercise a data protection right (such as access, correction or deletion), BLU will refer the request to the relevant Client and provide reasonable assistance to help the Client respond, since the Client controls that relationship and data.
8. Audit Rights
On reasonable written notice, a Client may request information reasonably necessary to confirm BLU's compliance with this page, which BLU will provide or make available for review, subject to confidentiality and security constraints.
9. Data Deletion
Upon termination of a Client's agreement with BLU, Client platform data is retained for a limited transition period to allow for export, after which it is permanently deleted in accordance with the applicable services agreement.
10. International Processing
Data may be processed in a jurisdiction other than the Client's own. Where this occurs, BLU takes steps to ensure an adequate level of protection consistent with applicable data protection law.
11. Contact Us
For data processing enquiries or to request a formal DPA, contact hello@goblu.tech.